APPLE-SA-2014-04-01-1Vendor advisory
http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html CVE-2014-1303
Sony Playstation 4 (PS4) < 2.50 - WebKit Code Execution (PoC)
Record summary
CVE-2014-1303 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits and 1 repository PoC.
Description
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBSony Playstation 4 (PS4) < 2.50 - WebKit Code Execution (PoC)ExploitDB exploitby TJ CorleyNot analyzed1 file
ExploitDBWebKitGTK 2.1.2 (Ubuntu 14.04) - Heap based Buffer OverflowExploitDB exploitby Ren KimuraNot analyzed1 file
Repository PoCs
GitHubRKX1209/CVE-2014-1303Repository PoCby RKX1209Stars: 24Not analyzed15 files
References
7APPLE-SA-2014-04-22-3Vendor advisory
http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html APPLE-SA-2014-04-22-2Vendor advisory
http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html twitter.com
http://twitter.com/thezdi/statuses/444157530139136000 pwn2own.com
http://www.pwn2own.com/2014/03/pwn2own-results-thursday-day-two nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-1303 support.apple.comConfirmation
https://support.apple.com/kb/HT6537